LIVE · cybersecurity feed
Live wire
US sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
nation-statecritical

US sanctions Iranian cyber actors as UK discloses power plant attack

The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.

zeroday.news ·

The United States has imposed sanctions on several Iranian nationals for their alleged involvement in cyberattacks targeting critical infrastructure, following reports of a cyber intrusion at a small power plant in the United Kingdom. Treasury Secretary Scott Bessent announced the new sanctions on Monday, August 24, 2026, as part of efforts to pressure the Iranian government and facilitate the reopening of the Strait of Hormuz.

Among those sanctioned are six individuals accused of operating as part of a hacking group within Iran’s Ministry of Intelligence and Security (MOIS). Four of these individuals—Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i, and Mojtaba Ghal’eh-Kuhi—were indicted last week. They are alleged to have breached employee email accounts associated with the U.S. Department of Labor, the Federal Energy Regulatory Commission, and multiple United Nations organizations. Two other individuals previously sanctioned were also named.

According to the Treasury Department, this group has been conducting cyberattacks on behalf of Iran’s MOIS since 2023, leading to "extensive compromises of U.S. critical infrastructure and financially motivated cyber theft." The MOIS is described as directing several networks of cyber threat actors engaged in cyber espionage to support Iran’s political objectives, including actions against American civilians.

Treasury officials stated that Blagh, Balujeh, and Kadkhoda’i were primarily responsible for the initial intrusions and data thefts. The group’s targets included critical infrastructure sectors such as energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions. Additionally, in the summer of 2024, they reportedly compromised multiple local, state, and federal government offices across the United States. The Treasury also noted that some members of the group are motivated by personal enrichment, prioritizing their own profits over MOIS operations, and have allegedly targeted Iranian companies or stolen cryptocurrency from local holders.

These sanctions come days after reports emerged of a cyber intrusion affecting a small power plant in the United Kingdom. While the incident reportedly shut down the plant for four days, no power loss to consumers occurred, and the overall power grid was unaffected. This incident has renewed concerns about the capability of Iranian actors to breach critical infrastructure organizations responsible for essential utilities.

In response to the UK incident, Energy Minister Michael Shanks stated on social media that the government had briefed energy CEOs and provided guidance on security measures. The FBI and National Security Agency had previously issued a warning last Wednesday about unnamed hackers targeting programmable logic controllers (PLCs), which are widely used in the energy, water, and agricultural industries.

Security experts have characterized the power plant attack as a significant escalation compared to previous targeting of water utilities. The incident reportedly involved an unsecured PLC. An adversary capable of accessing the main control system for a turbine or boiler could pose a substantial safety risk.

Iranian threat actors have been linked to several hacking campaigns since U.S. airstrikes against Iran began in February. These include recent attacks on water systems in at least 12 U.S. states. Iran has also claimed responsibility for cyberattacks on a prominent medical device company and the personal email account of the FBI director.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive branch.” The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

security

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'

vulnerability

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]

security

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

Glassbox dev admits he had some help from Claude to build locally running tool

malware

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.